Botan 3.6.1
Crypto and TLS for C&
Botan::Sphincs_Hash_Functions_Shake Class Reference

#include <sp_hash_shake.h>

Inheritance diagram for Botan::Sphincs_Hash_Functions_Shake:
Botan::Sphincs_Hash_Functions

Public Member Functions

std::tuple< SphincsHashedMessage, XmssTreeIndexInLayer, TreeNodeIndexH_msg (StrongSpan< const SphincsMessageRandomness > r, const SphincsTreeNode &root, const SphincsMessageInternal &message)
 
std::string msg_hash_function_name () const override
 
void PRF (StrongSpan< ForsLeafSecret > out, const SphincsSecretSeed &sk_seed, const Sphincs_Address &address)
 
void PRF (StrongSpan< WotsNode > out, const SphincsSecretSeed &sk_seed, const Sphincs_Address &address)
 
void PRF_msg (StrongSpan< SphincsMessageRandomness > out, StrongSpan< const SphincsSecretPRF > sk_prf, StrongSpan< const SphincsOptionalRandomness > opt_rand, const SphincsMessageInternal &msg) override
 
 Sphincs_Hash_Functions_Shake (const Sphincs_Parameters &sphincs_params, const SphincsPublicSeed &pub_seed)
 
template<typename OutT = std::vector<uint8_t>, typename... BufferTs>
OutT T (const Sphincs_Address &address, BufferTs &&... in)
 
template<typename... BufferTs>
void T (std::span< uint8_t > out, const Sphincs_Address &address, BufferTs &&... in)
 

Static Public Member Functions

static std::unique_ptr< Sphincs_Hash_Functionscreate (const Sphincs_Parameters &sphincs_params, const SphincsPublicSeed &pub_seed)
 

Protected Attributes

const SphincsPublicSeedm_pub_seed
 
const Sphincs_Parametersm_sphincs_params
 

Detailed Description

Implementation of SLH-DSA hash function abstraction for SHAKE256

Definition at line 21 of file sp_hash_shake.h.

Constructor & Destructor Documentation

◆ Sphincs_Hash_Functions_Shake()

Botan::Sphincs_Hash_Functions_Shake::Sphincs_Hash_Functions_Shake ( const Sphincs_Parameters & sphincs_params,
const SphincsPublicSeed & pub_seed )
inline

Definition at line 43 of file sp_hash_shake.h.

43 :
44 Sphincs_Hash_Functions(sphincs_params, pub_seed),
45 m_seeded_hash(sphincs_params.n() * 8),
46 m_hash(sphincs_params.n() * 8),
47 m_h_msg_hash(8 * sphincs_params.h_msg_digest_bytes()) {
48 m_seeded_hash.update(m_pub_seed);
49 }
void update(const uint8_t in[], size_t length)
Definition buf_comp.h:35
const SphincsPublicSeed & m_pub_seed
Definition sp_hash.h:103
Sphincs_Hash_Functions(const Sphincs_Parameters &sphincs_params, const SphincsPublicSeed &pub_seed)
Definition sp_hash.cpp:30

References Botan::Sphincs_Hash_Functions::m_pub_seed, and Botan::Buffered_Computation::update().

Member Function Documentation

◆ create()

std::unique_ptr< Sphincs_Hash_Functions > Botan::Sphincs_Hash_Functions::create ( const Sphincs_Parameters & sphincs_params,
const SphincsPublicSeed & pub_seed )
staticinherited

Creates a Sphincs_Hash_Functions object instantiating the hash functions used for the specified sphincs_params. The pub_seed is used to seed the hash functions (possibly padded). This is pre-computed and the respective state is copied on the further calls on H(seed) with tweak_hash, i.e., T and PRF.

Definition at line 34 of file sp_hash.cpp.

35 {
36 switch(sphincs_params.hash_type()) {
38#if defined(BOTAN_HAS_SPHINCS_PLUS_SHA2_BASE)
39 return std::make_unique<Sphincs_Hash_Functions_Sha2>(sphincs_params, pub_seed);
40#else
41 throw Not_Implemented("SLH-DSA (or SPHINCS+) with SHA-256 is not available in this build");
42#endif
43
45#if defined(BOTAN_HAS_SPHINCS_PLUS_SHAKE_BASE)
46 return std::make_unique<Sphincs_Hash_Functions_Shake>(sphincs_params, pub_seed);
47#else
48 throw Not_Implemented("SLH-DSA (or SPHINCS+) with SHAKE is not available in this build");
49#endif
50
52 throw Not_Implemented("Haraka is not implemented");
53 }
55}
#define BOTAN_ASSERT_UNREACHABLE()
Definition assert.h:137
@ Haraka
Haraka is currently not supported.

References BOTAN_ASSERT_UNREACHABLE, Botan::Haraka, Botan::Sphincs_Parameters::hash_type(), Botan::Sha256, and Botan::Shake256.

Referenced by Botan::SphincsPlus_PrivateKey::SphincsPlus_PrivateKey().

◆ H_msg()

std::tuple< SphincsHashedMessage, XmssTreeIndexInLayer, TreeNodeIndex > Botan::Sphincs_Hash_Functions::H_msg ( StrongSpan< const SphincsMessageRandomness > r,
const SphincsTreeNode & root,
const SphincsMessageInternal & message )
inherited

Definition at line 78 of file sp_hash.cpp.

79 {
80 const auto digest = H_msg_digest(r, root, message);
81
82 // The following calculates the message digest and indices from the
83 // raw message digest. See FIPS 205, Algorithm 19, Line 5-10.
84 const auto& p = m_sphincs_params;
85 BufferSlicer s(digest);
86 auto msg_hash = s.copy<SphincsHashedMessage>(p.fors_message_bytes());
87 auto tree_index_bytes = s.take(p.tree_digest_bytes());
88 auto leaf_index_bytes = s.take(p.leaf_digest_bytes());
89 BOTAN_ASSERT_NOMSG(s.empty());
90
91 auto tree_index = from_first_n_bits<XmssTreeIndexInLayer>(p.h() - p.xmss_tree_height(), tree_index_bytes);
92 auto leaf_index = from_first_n_bits<TreeNodeIndex>(p.xmss_tree_height(), leaf_index_bytes);
93 return {std::move(msg_hash), tree_index, leaf_index};
94}
#define BOTAN_ASSERT_NOMSG(expr)
Definition assert.h:59
const Sphincs_Parameters & m_sphincs_params
Definition sp_hash.h:102
virtual std::vector< uint8_t > H_msg_digest(StrongSpan< const SphincsMessageRandomness > r, const SphincsTreeNode &root, const SphincsMessageInternal &message)=0
Gf448Elem root(const Gf448Elem &elem)
Compute the root of elem in the field.
Strong< std::vector< uint8_t >, struct SphincsHashedMessage_ > SphincsHashedMessage
Definition sp_types.h:59

References BOTAN_ASSERT_NOMSG, Botan::BufferSlicer::copy(), Botan::BufferSlicer::empty(), Botan::Sphincs_Hash_Functions::H_msg_digest(), Botan::Sphincs_Hash_Functions::m_sphincs_params, Botan::root(), and Botan::BufferSlicer::take().

◆ msg_hash_function_name()

std::string Botan::Sphincs_Hash_Functions_Shake::msg_hash_function_name ( ) const
inlineoverridevirtual

Implements Botan::Sphincs_Hash_Functions.

Definition at line 62 of file sp_hash_shake.h.

62{ return m_h_msg_hash.name(); }
std::string name() const override
Definition shake.cpp:49

References Botan::SHAKE_256::name().

◆ PRF() [1/2]

void Botan::Sphincs_Hash_Functions::PRF ( StrongSpan< ForsLeafSecret > out,
const SphincsSecretSeed & sk_seed,
const Sphincs_Address & address )
inlineinherited

Definition at line 70 of file sp_hash.h.

70 {
71 T(out, address, sk_seed);
72 }
FE_25519 T
Definition ge.cpp:34

References T.

Referenced by Botan::fors_sign_and_pkgen(), and Botan::wots_sign_and_pkgen().

◆ PRF() [2/2]

void Botan::Sphincs_Hash_Functions::PRF ( StrongSpan< WotsNode > out,
const SphincsSecretSeed & sk_seed,
const Sphincs_Address & address )
inlineinherited

Definition at line 74 of file sp_hash.h.

74 {
75 T(out, address, sk_seed);
76 }

References T.

◆ PRF_msg()

void Botan::Sphincs_Hash_Functions_Shake::PRF_msg ( StrongSpan< SphincsMessageRandomness > out,
StrongSpan< const SphincsSecretPRF > sk_prf,
StrongSpan< const SphincsOptionalRandomness > opt_rand,
const SphincsMessageInternal & msg )
inlineoverridevirtual

Using SK.PRF, the optional randomness, and a message, computes the message random R, and the tree and leaf indices.

Parameters
outoutput location for the message hash
sk_prfSK.PRF
opt_randoptional randomness
msgmessage

Implements Botan::Sphincs_Hash_Functions.

Definition at line 51 of file sp_hash_shake.h.

54 {
55 m_hash.update(sk_prf);
56 m_hash.update(opt_rand);
57 m_hash.update(msg.prefix);
58 m_hash.update(msg.message);
59 m_hash.final(out);
60 }
void final(uint8_t out[])
Definition buf_comp.h:70

References Botan::Buffered_Computation::final(), Botan::SphincsMessageInternal::message, Botan::SphincsMessageInternal::prefix, and Botan::Buffered_Computation::update().

◆ T() [1/2]

template<typename OutT = std::vector<uint8_t>, typename... BufferTs>
OutT Botan::Sphincs_Hash_Functions::T ( const Sphincs_Address & address,
BufferTs &&... in )
inlineinherited

Definition at line 64 of file sp_hash.h.

64 {
65 OutT t(m_sphincs_params.n());
66 T(t, address, std::forward<BufferTs>(in)...);
67 return t;
68 }

References T.

◆ T() [2/2]

template<typename... BufferTs>
void Botan::Sphincs_Hash_Functions::T ( std::span< uint8_t > out,
const Sphincs_Address & address,
BufferTs &&... in )
inlineinherited

Definition at line 57 of file sp_hash.h.

57 {
58 auto& hash = tweak_hash(address, (std::forward<BufferTs>(in).size() + ...));
59 (hash.update(std::forward<BufferTs>(in)), ...);
60 hash.final(out);
61 }
virtual HashFunction & tweak_hash(const Sphincs_Address &address, size_t input_length)=0

Referenced by Botan::compute_root(), Botan::fors_public_key_from_signature(), Botan::fors_sign_and_pkgen(), Botan::ht_verify(), Botan::treehash(), and Botan::wots_sign_and_pkgen().

Member Data Documentation

◆ m_pub_seed

const SphincsPublicSeed& Botan::Sphincs_Hash_Functions::m_pub_seed
protectedinherited

Definition at line 103 of file sp_hash.h.

Referenced by Sphincs_Hash_Functions_Shake().

◆ m_sphincs_params

const Sphincs_Parameters& Botan::Sphincs_Hash_Functions::m_sphincs_params
protectedinherited

Definition at line 102 of file sp_hash.h.

Referenced by Botan::Sphincs_Hash_Functions::H_msg().


The documentation for this class was generated from the following file: